Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
121 commits
Select commit Hold shift + click to select a range
58b52ee
fix(daemon): preserve run state under event stream pressure (#626)
kunchenguid Aug 1, 2026
90885ee
fix(cimonitor): require trusted no-CI evidence for readiness (#628)
kunchenguid Aug 1, 2026
3a9e491
chore(main): release 1.44.2 (#627)
github-actions[bot] Aug 1, 2026
a93dc8f
fix(cli): confirm abort truth before releasing branch custody (#631)
kunchenguid Aug 2, 2026
1753783
feat(pipeline): re-run provider-cancelled CI checks before escalating…
mvanhorn Aug 2, 2026
c779d36
chore(main): release 1.45.0 (#632)
github-actions[bot] Aug 2, 2026
f2538db
fix(pipeline): independently review automatic fixes (#634)
kunchenguid Aug 2, 2026
cb567d7
chore(main): release 1.45.1 (#635)
github-actions[bot] Aug 2, 2026
eb826b4
fix(pipeline): stop polling terminal cancelled CI checks (#637)
kunchenguid Aug 2, 2026
c0920cd
fix(update): authenticate GitHub release requests (#636)
kunchenguid Aug 2, 2026
daf76f0
chore(main): release 1.45.2 (#638)
github-actions[bot] Aug 2, 2026
70e36b3
ci: prevent Windows test job timeouts (#645)
kunchenguid Aug 2, 2026
1c1fe5c
fix(pipeline): recognize green CI after successful rerun (#647)
kunchenguid Aug 3, 2026
73425eb
fix(branchsync): recover custody from contained rebased heads (#649)
kunchenguid Aug 3, 2026
6ed880d
chore(main): release 1.45.3 (#648)
github-actions[bot] Aug 3, 2026
eda3d33
fix(pipeline): restore deterministic PR body sections (#663)
kunchenguid Aug 4, 2026
0c58eb7
chore(main): release 1.45.4 (#664)
github-actions[bot] Aug 4, 2026
aead596
feat(pipeline): add structured step attestations to PR bodies (#670)
kunchenguid Aug 5, 2026
20892e6
chore(main): release 1.46.0 (#671)
github-actions[bot] Aug 6, 2026
d37d9cc
feat(evidence): publish artifacts to an orphan branch (#679)
kunchenguid Aug 7, 2026
a385367
fix(daemon): reap lingering run-worktree processes that escape their …
kunchenguid Aug 7, 2026
05e836b
chore(main): release 1.47.0 (#682)
github-actions[bot] Aug 7, 2026
5fc7bc7
feat(db): record build identity on run records (#687)
kunchenguid Aug 8, 2026
2ac3769
chore(main): release 1.48.0 (#688)
github-actions[bot] Aug 8, 2026
1712ac9
docs: update vision statement (#691)
kunchenguid Aug 9, 2026
331ee93
feat(eval): add local review evaluation toolkit (#701)
kunchenguid Aug 11, 2026
0fcd8e8
chore(main): release 1.49.0 (#702)
github-actions[bot] Aug 11, 2026
366dfce
feat(eval): automatically collect an affordable local corpus (#711)
kunchenguid Aug 12, 2026
89152aa
chore: remove committed no-mistakes evidence (now on orphan branch) (…
kunchenguid Aug 12, 2026
5335545
chore: gitignore no-mistakes evidence dir (contributor safety) (#715)
kunchenguid Aug 12, 2026
c4bc34b
chore(main): release 1.50.0 (#712)
github-actions[bot] Aug 12, 2026
a3954e1
feat(eval): score replay findings against human gold (#726)
kunchenguid Aug 14, 2026
f632c17
chore(main): release 1.51.0 (#727)
github-actions[bot] Aug 14, 2026
2498e75
fix(daemon): move test evidence out of system temp storage (#735)
kunchenguid Aug 14, 2026
2d8ec8a
chore(main): release 1.51.1 (#736)
github-actions[bot] Aug 14, 2026
5a36f2b
ci: split the Windows test leg and re-fix two CI flakes (#738)
kunchenguid Aug 15, 2026
dac4dc9
feat(eval): pin gold-only holdout and merge-derived finding gold (#739)
kunchenguid Aug 15, 2026
7cd86d4
feat(pipeline): ungate review counterexample tracing and name silent-…
kunchenguid Aug 15, 2026
f92b7bd
feat(eval): ingest confirmed post-PR misses as false-negative gold (#…
kunchenguid Aug 15, 2026
a68298e
feat(pipeline): persist uncertified fixer commits for the next initia…
kunchenguid Aug 15, 2026
39898db
chore(main): release 1.52.0 (#742)
github-actions[bot] Aug 16, 2026
f808d23
feat(eval): label findings by recorded decision and match gold global…
kunchenguid Aug 16, 2026
f627beb
chore(main): release 1.53.0 (#754)
github-actions[bot] Aug 16, 2026
6859d1e
chore(agents): use @AGENTS.md import instead of CLAUDE.md symlink (#758)
kunchenguid Aug 17, 2026
8facba5
feat(eval): add dashboards and idempotent eval workflows (#779)
kunchenguid Aug 19, 2026
f41b730
chore(main): release 1.54.0 (#780)
github-actions[bot] Aug 19, 2026
3edab07
feat(cli): improve eval sets repository and matrix display (#784)
kunchenguid Aug 19, 2026
3cf6786
chore(main): release 1.55.0 (#785)
github-actions[bot] Aug 19, 2026
a076b87
fix(eval): prevent display state mutations and clipped strata (#787)
kunchenguid Aug 19, 2026
a4411ed
fix(pipeline): preserve declined finding decisions across runs (#790)
kunchenguid Aug 20, 2026
ac15daf
chore(main): release 1.55.1 (#788)
github-actions[bot] Aug 20, 2026
6dc07a4
fix(agent): prefer closed JSON fences over unclosed pi tails
onyx-space Aug 20, 2026
f345f6a
fix(pipeline): preserve existing PR's forge base branch for CI repair…
eeshaansarda Aug 20, 2026
7186c4b
feat(daemon): place run worktrees per repository via worktree_roots
rudingma Aug 20, 2026
3ed3ca4
fix(agent): support structured output with thinking models
deeto15 Aug 20, 2026
132fb10
fix(agent): harden stdin prompt delivery
andrew-kim-techtorch Aug 20, 2026
abe6da6
fix(pipeline): render Bitbucket Cloud PR bodies as no-HTML markdown
tmaffia Aug 20, 2026
4c58ac3
feat(agent): add native Grok Build support
p3ngu1nx Aug 20, 2026
53849a4
fix(daemon): preserve open PR when daemon restarts during CI monitori…
mvanhorn Aug 20, 2026
5c7f815
feat(scm): add Forgejo provider support (#718)
escidmore Aug 20, 2026
628d688
fix(github): include head workflow runs in CI readiness (#616)
LinusSkippy Aug 20, 2026
3bae1b9
chore(main): release 1.56.0 (#793)
github-actions[bot] Aug 21, 2026
595a32a
fix(pipeline): bypass hooks for correction commits (#796)
jjaguirr Aug 21, 2026
8d6ebbf
fix(branchsync): isolate and configure remote operation timeouts (#684)
rega10 Aug 21, 2026
59c8a73
ci: require completed review, test, and document attestation (#797)
kunchenguid Aug 21, 2026
1217415
fix(pr): separate mixed evidence blocks (#800)
deeto15 Aug 21, 2026
70d7d8c
fix(review): bound stalled review agents (#708)
Julian-Dasilva Aug 21, 2026
b00db34
feat(agent): add Antigravity (agy) support (#673)
chorned Aug 21, 2026
b39624f
chore: enable pi session resume (#802)
tobijdc Aug 21, 2026
88b322f
fix(scm): fail closed on invalid PR listings (#470)
ShiroKSH Aug 21, 2026
f2e9289
feat(agent): unify model and effort configuration (#806)
kunchenguid Aug 21, 2026
21f3793
fix(pipeline): prevent test agents from hanging runs (#807)
kunchenguid Aug 21, 2026
4a5cec6
fix(pipeline): bound every agent invocation by a timeout (#810)
kunchenguid Aug 21, 2026
5b89741
fix(branchsync): preserve recoverable pipeline custody (#803)
deeto15 Aug 22, 2026
9e6400c
feat(agent): resume antigravity conversations for review-fixer sessio…
khaira777 Aug 22, 2026
5dbbb3a
test(e2e): add antigravity fixture recording and replay coverage (#809)
khaira777 Aug 22, 2026
8685603
fix(branchsync): correct custody recovery eligibility (#814)
deeto15 Aug 22, 2026
287e8dc
fix(agent): map agy thinking tokens and honor the terminal result res…
khaira777 Aug 22, 2026
0fcbbff
chore(main): release 1.57.0 (#798)
github-actions[bot] Aug 22, 2026
22a32b2
fix: make git fetch cancellation converge (#752)
mvanhorn Aug 22, 2026
a6f64fc
chore(main): release 1.57.1 (#816)
github-actions[bot] Aug 22, 2026
c82cfe8
feat(scm): add Gitea as a fifth SCM provider (#789)
babbarc Aug 22, 2026
c2a75d0
fix(pipeline): park CI step at ask-user gate on persistent check-read…
vipentti Aug 22, 2026
c0e06be
refactor(agent): replace antigravity map-based stream parsing with ty…
khaira777 Aug 22, 2026
32d396a
feat: add shared no-mistakes PR enforcement action (#819)
kunchenguid Aug 22, 2026
bbd769f
fix(pipeline): retry GitHub Actions pre-run infrastructure failures (…
karotkriss Aug 23, 2026
a38a55b
ci: migrate PR gate to shared action (#821)
kunchenguid Aug 23, 2026
5b337f4
docs: record fleet migration invariants for the shared PR-enforcement…
kunchenguid Aug 23, 2026
ea8ecb0
fix: replace the running executable during Windows self-update (#650)
mvanhorn Aug 23, 2026
fb94645
feat(pipeline): surface missing host permissions in test evidence (#491)
ss251 Aug 23, 2026
45dd6ed
chore(main): release 1.58.0 (#818)
github-actions[bot] Aug 23, 2026
8dc5c15
fix(pipeline): revalidate CI repairs before push (#827)
nikolauska Aug 23, 2026
c878873
fix(pipeline): redact home-directory paths from published PR content …
dmealing Aug 23, 2026
5a4e1a8
chore(main): release 1.58.1 (#829)
github-actions[bot] Aug 24, 2026
cc8d52a
feat(forgecontext): route provider identity per repository with pinne…
rudingma Aug 24, 2026
cd5f5ba
fix(agent): surface opencode's failed-turn error instead of empty out…
nickjg1 Aug 25, 2026
93dfb91
chore(main): release 1.59.0 (#835)
github-actions[bot] Aug 25, 2026
3781331
fix(scm/gitlab): drop unsupported --yes flag from glab mr update (#841)
karotkriss Aug 25, 2026
9694fff
fix(agent): harden isolated pipeline execution (#844)
khaira777 Aug 26, 2026
36e8fa8
chore(main): release 1.59.1 (#843)
github-actions[bot] Aug 26, 2026
539f09a
fix(pipeline): recognize push provenance to allow pushing rebased pip…
khaira777 Aug 26, 2026
a59d667
fix(scm): collapse superseded GitHub check runs (#855)
kunchenguid Aug 26, 2026
10cb727
fix(cli): scope AXI run resolution to the current branch (#850)
tiago-peixoto Aug 26, 2026
9d4de6a
chore(main): release 1.59.2 (#853)
github-actions[bot] Aug 26, 2026
06c6504
fix(update): reap background update-check processes (#858)
kunchenguid Aug 27, 2026
8833bff
docs(fork): record semantic main reconciliation
Aug 27, 2026
dcb6e66
chore(fork): reconcile preserved main ancestry
Aug 27, 2026
67b4249
chore(fork): preserve release-please generated state
Aug 28, 2026
2633907
fix(sonar): extract duplicated string literals into named constants
Aug 28, 2026
e941aab
style(config): align constant map entries with gofmt
Aug 28, 2026
0f09b43
fix(sonar): extract duplicated git fetch flag literals into named con…
Aug 28, 2026
f78e829
no-mistakes(ci): Fixed SonarCloud duplicate-literal issue in internal…
Aug 28, 2026
0c793e0
revert(ci): remove unreproducible host-built binary
Aug 28, 2026
f3e2ca6
no-mistakes(ci): Fixed SonarCloud duplicate-literal issue in internal…
Aug 28, 2026
6673317
fix(review): address fork reconciliation findings
Aug 29, 2026
c8f4a97
test(daemon): rely on behavioral agent coverage
Aug 29, 2026
ef3c941
fix(ci): restore security and protection gates
Aug 29, 2026
fb85ee8
test: centralize repeated integration fixtures
Aug 29, 2026
b5cc49e
test(e2e): align base runtime deadline
Aug 29, 2026
654c35d
test(github): distinguish same-name check sources
Aug 29, 2026
68c4a79
test(pipeline): centralize correction fixtures
Aug 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
239 changes: 239 additions & 0 deletions .agent/exec-plans/completed/execplan-native-grok-agent.md

Large diffs are not rendered by default.

6 changes: 6 additions & 0 deletions .agent/exec-plans/tech-debt-tracker.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
# Tech Debt Tracker

Accumulated tech debt from exec-plans. Review before starting new plans.

| Date | Source Plan | Description | Priority | Status |
|---|---|---|---|---|
248 changes: 0 additions & 248 deletions .circleci/config.yml

This file was deleted.

135 changes: 135 additions & 0 deletions .github/actions/require-no-mistakes/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,135 @@
# `require-no-mistakes`

Composite action that checks whether a pull request body declares a completed,
head-bound no-mistakes pipeline run. It is the reusable shared implementation
of the check named **`PR must be raised via no-mistakes`**; enforcing
repositories can call it instead of copying the shell into their own workflow.

It verifies, in order:

1. the PR body carries the no-mistakes signature line;
2. the body carries a parseable `<!-- no-mistakes-pipeline-attestation:v1 {...} -->`
comment;
3. the attestation's `head_sha` equals the PR head SHA, so a later push cannot
pass on an older attestation;
4. `review`, `test`, and `document` each recorded `status == "completed"`.
Quota skips and agent skips are not compliant.

Missing or unparseable attestation reports the no-mistakes `>= 1.46.0` floor;
a missing signature reports the not-raised-via-no-mistakes guidance.

## Usage

Consumers pin a release tag or a commit SHA. Never `@main`: `main` is editable
by the very PR the gate is judging.

```yaml
name: Require no-mistakes
on:
pull_request:
types: [opened, edited, reopened]
branches: [main]

permissions:
contents: read

jobs:
check:
name: PR must be raised via no-mistakes
runs-on: ubuntu-latest
steps:
- uses: kunchenguid/no-mistakes/.github/actions/require-no-mistakes@<release-tag-or-sha>
with:
exempt-authors: |
github-actions[bot]
dependabot[bot]
```

Replace `<release-tag-or-sha>` with a no-mistakes release tag or commit SHA
that contains this action.

The job name must stay exactly `PR must be raised via no-mistakes` so branch
rulesets keep matching the same check across the fleet.

An ordinary `pull_request`-triggered caller forwards no PR facts: the action
reads the body, head SHA, head branch, author, and number from the workflow
event payload. Pass the `pr-*` inputs only when driving it from another event.

## Inputs

| Input | Default | Purpose |
| --- | --- | --- |
| `exempt-authors` | `""` | Newline- or comma-separated author logins that bypass the gate (automation accounts that cannot be routed through the pipeline). |
| `exempt-bot-authors` | `false` | When true, every `*[bot]` author bypasses the gate. |
| `exempt-head-branches` | `""` | Glob patterns; a matching head branch bypasses the gate, for structural automation branches such as `release-please--*`. |
| `pr-body`, `pr-head-sha`, `pr-head-ref`, `pr-author`, `pr-number` | `""` | Override the corresponding event-payload fact. |

Which steps are required is deliberately **not** an input. A caller configures
who is exempt, never what the gate certifies, so no repository can weaken the
check while still reporting the same name.

## Outputs

| Output | Meaning |
| --- | --- |
| `compliant` | `true` only when the PR satisfied the pipeline gate. It remains `false` for an exemption because bypass is not validation. |
| `exempt` | `true` when a configured exemption bypassed the gate. |
| `exempt-reason` | Why the PR was exempt; empty when it was judged. |

## Boundary

The action never checks out or executes repository code, so it is safe on
`pull_request` runs from forks. Callers should keep `permissions: contents: read`
and stay on `pull_request` rather than `pull_request_target`.

An exemption is trusted outer-repository policy supplied by the caller's pinned
workflow. It does not claim that no-mistakes ran: exempt PRs report
`compliant=false` and `exempt=true`. This is separate from the invariant that no
standing configuration may skip a step inside a no-mistakes run.

### Non-goal: a contributor guardrail, not a forgery-proof boundary

This gate is a **contributor guardrail**. It is explicitly **not** a
forgery-proof security boundary, and it is not trying to become one.

The attestation is a deterministic, commit-bound declaration published in the
PR body, not a cryptographic signature. A pull request author can edit their own
body and reproduce the documented format by hand, and such a PR passes this
check. That is a **known and accepted limitation**, and a **pre-existing** one:
it is inherited verbatim from the inline gate this action extracts, so
consolidating the fleet onto one implementation neither introduces nor widens
it. The action emits a warning on every structural pass to keep the boundary
visible in the required check's logs.

What it does reliably catch is the case it exists for: a contributor who
bypassed the pipeline by accident, a malformed or incomplete declaration, and an
attestation left stale by a later push. It authorizes nothing against an author
who forges the format on purpose.

Authenticated (signed) attestations are the robust fix. They are tracked
separately as backlog item `nm-signed-attestations-r1` and are deliberately out
of scope for this action.

## Rollout

This repository's own gate (`.github/workflows/no-mistakes-required.yml`) is a
thin caller of this action, pinned to the commit that first published it. GitHub
downloads `uses:` actions at job setup, so the pin must always name a ref that
already carries the action; a caller pinned to a tag that predates it fails
closed on every pull request.

Pinning the gate to an already-published commit is the self-certification guard.
A pull request that edits this action is fully **tested** on its own head - the
repository's Go tests execute `verify.py` from the working tree - while the
required check judging that pull request keeps running the published pinned copy. The
gate is therefore never rewritten by the change it is judging. Bumping the pin
is a deliberate, separate pull request.

Migrating the other enforcing repositories follows the same rule: pin a released
tag or a commit SHA, never `@main`.

## Behavior is pinned by tests

`require_no_mistakes_action_test.go` in the repository root executes
`verify.py` the way a runner does and covers every verdict, the exemption
surface, and the event-payload fallback.
Loading
Loading